|
246471
|
6.5 |
MEDIUM
Network
|
libpng oracle
|
libpng jdk jre
|
An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.
|
NVD-CWE-noinfo
|
CVE-2018-14048
|
2024-11-21 12:48 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246472
|
5.5 |
MEDIUM
Local
|
pngwriter_project
|
pngwriter
|
An issue has been found in PNGwriter 0.7.0. It is a SEGV in pngwriter::readfromfile in pngwriter.cc. NOTE: there is a "Warning: PNGwriter was never designed for reading untrusted files with it. Do NO…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14047
|
2024-11-21 12:48 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246473
|
8.8 |
HIGH
Network
|
exiv2
|
exiv2
|
Exiv2 0.26 has a heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-14046
|
2024-11-21 12:48 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246474
|
7.5 |
HIGH
Network
|
surina
|
soundtouch
|
The FIRFilter::evaluateFilterMulti function in FIRFilter.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and applicati…
|
CWE-617
Reachable Assertion
|
CVE-2018-14045
|
2024-11-21 12:48 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246475
|
7.5 |
HIGH
Network
|
surina
|
soundtouch
|
The RateTransposer::setChannels function in RateTransposer.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and applica…
|
CWE-617
Reachable Assertion
|
CVE-2018-14044
|
2024-11-21 12:48 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246476
|
9.8 |
CRITICAL
Network
|
monetra
|
mstdlib
|
mstdlib (aka the M Standard Library for C) 1.2.0 has incorrect file access control in situations where M_fs_perms_can_access attempts to delete an existing file (that lacks public read/write access) …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-14043
|
2024-11-21 12:48 |
2018-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246477
|
6.1 |
MEDIUM
Network
|
getbootstrap
|
bootstrap
|
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14042
|
2024-11-21 12:48 |
2018-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246478
|
6.1 |
MEDIUM
Network
|
getbootstrap
|
bootstrap
|
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14041
|
2024-11-21 12:48 |
2018-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246479
|
6.1 |
MEDIUM
Network
|
debian getbootstrap
|
debian_linux bootstrap
|
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14040
|
2024-11-21 12:48 |
2018-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246480
|
6.5 |
MEDIUM
Network
|
freedesktop
|
accountsservice
|
Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.
|
CWE-22
Path Traversal
|
CVE-2018-14036
|
2024-11-21 12:48 |
2018-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|